cat ~/cv
Lukas Weichselbaum
Chronological record: roles, levels, and what shipped in each.
The narrative
version lives on the main page.
google · zürich
2023 – nowSenior Staff (L7) · Manager
AI Agent Security & Web Security
- Anticipated the security implications of LLMs touching sensitive data and privileged actions; bootstrapped Google's first AI Agent Security team, focused on securing AI agents against prompt injection, rogue actions and sensitive-data exfiltration.
- The team's work is a core part of Google's public Secure AI Framework: launched the company-wide Agent Security Policy; helps secure Gemini and Search AI Mode in practice. Team published "Google's Approach for Secure AI Agents", among the most-cited papers in agent security.
- In parallel, set the three-part Agentic Web Security strategy — using agents to change how classical security gets done: find agents (built-in validation, zero false positives), patching agents upstreamed into DeepMind's CodeMender, and safe-coding training for the underlying models.
- Lead both security organizations today — ~25 engineers worldwide: manage managers as well as engineers, and built the agent team by hiring in the industry's most competitive talent market.
2018 – 2023Staff → Senior Staff (L6 → L7)
Lead, Google's web security org
- Built and led the organization securing Google's flagship web apps — Gmail, Photos, Drive among them — and grew the team past 20 engineers across Zürich, New York, Sunnyvale and Seattle: six subteams, from hardening to outreach.
- Drove strict CSP, Trusted Types, Fetch Metadata, COOP and CORP across hundreds of Google's most sensitive domains; today they protect the majority of Google's sensitive Front End traffic. XSS in core products fell 90% over the decade, and apps on the hardened frameworks average under one XSS report a year in total.
- Led multi-year collaborations with Mozilla, Apple and Igalia to bring Trusted Types, Fetch Metadata and CSP3 to Firefox and Safari. After six years, Trusted Types now ships in every major browser engine (Chrome, Safari, Firefox).
- Bootstrapped Product Security Measurability; co-authored Security Signals (8,000+ services, ~1,000 domains, trillions of requests; used by 60+ teams, tripled scan coverage for internal services); defined Long-Lived Stable Metrics for Web Security, Memory Safety and Crypto Hygiene. Synthetic-signals approach patent-pending (US 2026/0119646 A1, with Spagnuolo and Janc).
2016 – 2018Senior → Staff (L5 → L6)
Web platform security & standards
- W3C WebAppSec WG: CSP Level 3. Introduced strict-dynamic, moving CSP from domain allowlists to deployable nonces and hashes. The pattern now runs on 30%+ of global page loads.
- Architected the strict CSP rollout across Gmail, Docs, Drive, Cloud Console, Accounts and hundreds more: phased, months-long deployments with no critical outage.
- Built the CSP violation-report telemetry pipeline (billions of reports/day) to scale and automate rollouts.
2015 – 2016SWE → Senior (L4 → L5)
Web security research
- Internet-scale CSP study (~100B pages, 1.68M hosts, 26k unique policies): 94.7% of policies that tried to limit scripts were bypassable → "CSP Is Dead, Long Live CSP!" (ACM CCS 2016).
- Built and open-sourced CSP Evaluator, now in Chrome DevTools and Lighthouse. 200,000+ users a year.
2013 – 2015SWE (L3 → L4)
Vendor Security
- Security audits and red teaming across Google's third-party supply chain.
- Built the vendor assessment remediation platforms and open-sourced Google's vendor assessment questionnaire: VSAQ — standardized risk reviews across thousands of suppliers and cut time-to-remediation.
2012
Software engineering intern — Google, Mountain ViewJul – Oct 2012
before google
2012
secLab, Technical University of Vienna — researchCo-built Andrubis: dynamic analysis of Android
malware at scale,
1,000,000+ apps analysed.
2009 – 2013
SEC Consult, Vienna — security consultant60+ audits and forensic engagements for national and
international clients; multi-day security trainings; trained new staff.
education
2012 – 2015
MSc Software Engineering & Internet Computing — Technical University of ViennaCompleted from
Zürich alongside
full-time work. Thesis: Andrubis — Dynamic Behavior Monitoring of Android Malware.
2009 – 2012
BSc Software & Information Engineering — Technical University of Vienna2× merit
scholarship.
2003 – 2008
HTL St. Pölten — EDP & OrganisationMatura, 1.0 grade average.
recognition & service
- 4× Senior-Vice-President-level Google Impact Awards — for project quality and team leadership
- Programme committees / peer review: NDSS MADWeb, USENIX WOOT (×2)
- Guest lectures: ETH Zürich, KTH Stockholm, Technical University of Vienna, Chalmers, FH St. Pölten
- gMentors (Alphabet-wide mentoring) · L6 promotion & hiring committees
- Mentored several engineers to Staff and Senior Staff
- Certifications: CompTIA Security+, SCJP, CCNA, MCP, Cambridge BEC